Rhode Island 2025 Regular Session

Rhode Island House Bill H6346

Introduced
5/16/25  

Caption

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

Impact

One significant aspect of H6346 is its requirement for municipal and state agencies to establish and maintain a risk-based information security program. This program must align with current best practices of an approved cybersecurity framework and define reasonable security procedures to protect personal data. Moreover, the bill mandates timely notification to affected individuals in the event of a data breach, reinforcing the accountability of agencies responsible for handling personal information.

Summary

House Bill H6346 aims to amend the Identity Theft Protection Act of 2015 by redefining key terms and increasing penalties for violations. Notably, the bill eliminates outdated definitions such as 'classified data' and 'personal information', replacing them with a clarified term 'personally identifiable information'. This amendment seeks to strengthen protection measures regarding personal data in light of evolving cybersecurity threats, thereby enhancing the overall framework of identity theft protections in Rhode Island.

Contention

While the overall intent of the bill appears beneficial in improving data security, there may be contention surrounding the effectiveness and feasibility of the notification requirements. Critics could argue that the strict timelines for notifications could impose additional burdens on entities that could already be struggling to manage cybersecurity incidents. The bill also increases penalties for violations, which some may view as excessively punitive, especially for smaller agencies or businesses.

Companion Bills

No companion bills found.

Previously Filed As

RI H5684

Identity Theft Protection Act Of 2015

RI S0425

Identity Theft Protection Act Of 2015

RI H7281

Amends the statutory provisions regarding domestic and foreign insurers and insurer examinations to provide provisions with regard to cybersecurity events involving Rhode Island consumers.

RI S2802

Amends the statutory provisions regarding domestic and foreign insurers and insurer examinations to provide provisions with regard to cybersecurity events involving Rhode Island consumers.

RI H7282

Amends outdated provisions of the banking statutes and the home loan protection act, adds consumer protections, including minimum capital requirements and limits on investments, for currency transmitters, including crypto currency.

RI S2803

Amends outdated provisions of the banking statutes and the home loan protection act, adds consumer protections, including minimum capital requirements and limits on investments, for currency transmitters, including crypto currency.

RI S0754

General Regulatory Provisions -- Rhode Island Data Transparency And Privacy Protection Act

RI H6236

General Regulatory Provisions -- Rhode Island Data Transparency And Privacy Protection Act

RI S2956

Amends several provisions relative the powers and duties of the PUC and requires the submission by utilities of integrated distribution system plans identifying solutions to reduce greenhouse gases.

RI H5457

Definitions And General Code Provisions

Similar Bills

RI S1037

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

CA AB2777

Office of Information Security: Baseline Information Security Score.

NJ S3100

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ A1981

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

NJ A2200

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

AL HB68

State government, Office of Information Technology, cybersecurity requirements, provided

NJ A5822

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

CA AB2135

Information security.